Network Security Segment Negotiation via Device Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network management systems face inefficiencies and security risks due to reliance on conventional network devices making decisions about network segment associations without full awareness of all network activities, leading to potential security breaches and manual labor-intensive configurations.

Innovation Solution

A method where network devices obtain security update information from communication devices to determine the appropriate security segment based on changes in their profiles, reducing the risk of security breaches and improving network security by actively involving communication devices in segment association decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional network devices make decisions about network segment associations entirely on their own, then network management is simplified, but network security is compromised due to lack of awareness of all network activities

Engineering Contradiction:
Improvenetwork managementVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where communication devices provide security update information to network devices. This allows network devices to make informed segmentation decisions based on real-time security status changes, resolving the contradiction by maintaining simplified management while improving security awareness through device feedback

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Communication devices autonomously generate and transmit security update information when their security profiles change. This self-service approach enables network devices to receive accurate security data without manual intervention, enhancing security while keeping management automated

Inventive Principle:
Principle #25Self-service

2Extent of automation

If network devices assign security segments without communication device input, then configuration is automated, but segment mismatches occur leading to security risks

Engineering Contradiction:
Improvenetwork configurationVSAvoidsegment assignment accuracy
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The system uses feedback from communication devices about their security profile changes to improve segmentation accuracy. Devices report when their security status changes, allowing network devices to reassign segments appropriately, maintaining automation while reducing mismatches

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements dynamic segment assignment where security segments are not fixed but can be reassigned based on changing security profiles. This dynamic approach allows automated configuration to adapt to new security conditions, improving assignment accuracy without reducing automation

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If communication devices use alternate networks bypassing regular channels, then communication flexibility is improved, but network device awareness is reduced creating security gaps

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidnetwork activity visibility
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent establishes a feedback channel where communication devices transmit security update information directly to network devices even when using alternate networks. This ensures network devices remain aware of security-relevant activities regardless of the communication path used, maintaining flexibility while preventing information loss

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12155695B2Executing security negotiation for network configuration
Publication Date: 2024.11.26 HUAWEI TECH CO LTD
  • US12155695B2 patent drawing
  • US12155695B2 patent drawing
  • US12155695B2 patent drawing

AI summary

A method for executing a security negotiation for a network configuration at a network device, includes obtaining, by the network device, a security update information from a communication device being assigned to a first security segment. The first security segment is associated with a first segment security profile. The security update information is indicative of at least one change in a first security profile of the communication device. The method further includes determining, by the network device, a second security segment for the communication device based on the security update information. An instruction is provided by the network device to the communication device to join the determined second security segment.